Legal

Privacy Policy

Last updated: 19 July 2026. Lees dit in het Nederlands ↓

NRL Social Centre ("the Platform") is operated by NRL Automations ("we", "us"), Niek Beerens, contactable at niek@nrlautomations.com. This policy explains what personal data we collect, why, and how it is protected, for anyone using the Platform, including through a white-label instance operated by one of our agency partners on their own subdomain.

1. What data we collect

  • Account data: name, email address, and a securely hashed password. If you enable two-factor authentication, we store the verified state of your authenticator, never the underlying secret in plain text.
  • Workspace/agency data: your business or workspace name, contact details, and branding settings you configure.
  • Connected third-party data, only if and after you explicitly connect an account via "Connect with Facebook" or a similar flow: OAuth access tokens (stored encrypted, never in plain text, and never visible to us or anyone else in the interface), your connected Facebook Page and Instagram Business account identifiers and public profile stats (username, follower count, media count), your ad account identifiers and advertising performance metrics, and the content of Instagram/Facebook direct message conversations you choose to view or reply to from the dashboard.
  • Usage data: sign-in timestamps, feature usage, and AI-generation logs (token/cost usage) used to enforce spending limits you or your agency configure.

2. How we use it

We use this data to operate the dashboard you signed up for: to show your own Instagram/Facebook/ads analytics, to let you read and reply to your own direct messages, to generate AI story-sequence content on your behalf, to secure your account, and to enforce any spending caps configured for AI usage. We do not use your data to train any third-party AI model, and we do not sell your data to anyone.

3. Legal basis (GDPR)

We process your data to perform the contract you enter into by using the Platform, on the basis of our legitimate interest in keeping the service secure and functioning, and, where Meta or Google require it, on the basis of the consent you explicitly grant during the "Connect with Facebook" / Google sign-in flow (you choose exactly which permissions to grant, and can revoke them at any time).

4. Where your data is stored, and who processes it

  • Supabase (database, authentication): hosted in the EU (Frankfurt, Germany).
  • Vercel (application hosting): may process data in the United States under standard contractual clauses.
  • Anthropic (Claude API): only processes the specific content needed to generate AI story sequences, and only when an AI connection is configured for your workspace.
  • Meta Platforms, Inc. and Google LLC: the source of any Instagram, Facebook, or YouTube data you choose to connect; their own privacy policies govern how they handle your account on their platforms.

We do not share your data with any other third party, and we never sell it.

5. YouTube API Services and Google user data

The Platform's YouTube features use YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.

  • After you connect your channel through Google sign-in, we access, collect and store: your channel's basic data (title, subscriber count, and the video list with titles, thumbnails and durations) and its analytics (views, watch time, likes, comments, shares, subscriber changes, and per-video statistics). This data is used solely to show your own channel's dashboard to you and your managing agency, is stored encrypted within your workspace, and is never shared with, sold, or transferred to any other party.
  • Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: Google user data is used only for the user-facing dashboard features described here, never for advertising, and is never sold.
  • You can revoke the Platform's access to your Google/YouTube data at any time via Settings → Connections → Disconnect in the dashboard, or via your Google security settings page.
  • When you disconnect in the dashboard, the stored YouTube data for that connection is deleted immediately. If you revoke access via Google's security settings page instead, stored YouTube data is deleted within 30 days of the revocation.

6. How long we keep it, and how to delete it

In short: you are always in control. You can disconnect any integration yourself at any time, and you can request full account deletion. Both are described step by step on our Data Deletion page; the summary:

  • Disconnecting an integration (Settings → Connections → Disconnect) deletes its stored access tokens immediately. We keep only a minimal record that the integration once existed (the connected account name and the connection/disconnection dates) so you can see your integration history if you reconnect; that record is removed when the workspace itself is deleted.
  • Deleting your account removes your login and profile everywhere on the Platform right away. If you were the sole member of a client workspace, that entire workspace, including any connected access tokens, direct-message history, advertising data, and AI-generated content, is permanently deleted in the same action, not retained. If your workspace has other team members or is managed by an agency, only your own access is removed; the shared workspace and its data stay intact for the remaining team, and you should contact your agency directly to have shared data removed too.
  • Backups: like most hosting providers, our database and hosting providers keep routine security backups for disaster recovery. Deleted data may persist in these backups for a limited rotation window before being purged automatically; we do not restore or access backups except to recover from a genuine incident.
  • Some records (for example, billing or fraud-prevention logs) may be retained for a short period where we are legally required to, but never longer than necessary and never including your third-party access tokens or message content.

7. Security

Third-party access tokens are encrypted at rest (AES-256-GCM) and are never displayed in the interface, not even to your own agency's staff. Every workspace is isolated at the database level (row-level security), so one workspace can never read another's data. Two-factor authentication is available on every account. All traffic is encrypted in transit (TLS).

8. Your rights

Under GDPR and comparable laws, you may request access to, correction of, or erasure of your personal data, and may object to or restrict certain processing. Contact niek@nrlautomations.com to exercise any of these rights; we respond within 30 days.

9. Children

The Platform is a business tool and is not directed at, or knowingly used by, children under 16.

10. Changes to this policy

We may update this policy as the Platform evolves. Material changes will be reflected by the "Last updated" date above.

11. Contact

NRL Automations, Niek Beerens, niek@nrlautomations.com


↑ Read this in English

Privacyverklaring

NRL Social Centre ("het Platform") wordt beheerd door NRL Automations ("wij"), Niek Beerens, te bereiken via niek@nrlautomations.com. Deze verklaring legt uit welke persoonsgegevens we verzamelen, waarom, en hoe die beveiligd zijn, voor iedereen die het Platform gebruikt, ook via een white-label omgeving van een van onze agency-partners op hun eigen subdomein.

1. Welke gegevens we verzamelen

  • Accountgegevens: naam, e-mailadres en een veilig gehasht wachtwoord. Bij tweestapsverificatie bewaren we alleen de geverifieerde status, nooit de onderliggende sleutel in platte tekst.
  • Werkruimte/agency-gegevens: je bedrijfs- of werkruimtenaam, contactgegevens en de huisstijl die je instelt.
  • Gekoppelde externe gegevens, alleen als en nadat je zelf een account koppelt via "Connect with Facebook" of vergelijkbaar: OAuth-tokens (versleuteld opgeslagen, nooit in platte tekst, en nooit zichtbaar in de interface voor ons of iemand anders), je gekoppelde Facebook-pagina en Instagram-bedrijfsaccount met publieke profielcijfers (gebruikersnaam, aantal volgers, aantal posts), je advertentie-account-ID's en advertentiecijfers, en de inhoud van Instagram/Facebook-gesprekken die je zelf bekijkt of beantwoordt vanuit het dashboard.
  • Gebruiksgegevens: inlogmomenten, functiegebruik, en AI-generatielogs (token/kosten-gebruik) om eventuele uitgavenlimieten te handhaven.

2. Waarvoor we het gebruiken

We gebruiken deze gegevens om het dashboard te leveren waarvoor je je hebt aangemeld: om je eigen Instagram/Facebook/advertentiecijfers te tonen, je eigen directe berichten te lezen en beantwoorden, AI-story-content voor je te genereren, je account te beveiligen, en eventuele uitgavenlimieten te handhaven. We gebruiken je gegevens nooit om een extern AI-model te trainen, en verkopen je gegevens nooit aan wie dan ook.

3. Grondslag (AVG)

We verwerken je gegevens ter uitvoering van de overeenkomst die ontstaat door het Platform te gebruiken, op basis van ons gerechtvaardigd belang bij een veilige en werkende dienst, en waar Meta of Google dat vereisen, op basis van de toestemming die je expliciet geeft tijdens de koppel-stap (je kiest zelf precies welke permissies je verleent, en kunt die op elk moment intrekken).

4. Waar je gegevens staan, en wie ze verwerkt

  • Supabase (database, authenticatie): gehost in de EU (Frankfurt, Duitsland).
  • Vercel (hosting van de applicatie): kan gegevens verwerken in de Verenigde Staten onder standaard modelcontractbepalingen.
  • Anthropic (Claude API): verwerkt alleen de content die nodig is om AI-story-sequences te genereren, en alleen als er een AI-koppeling voor je werkruimte is ingesteld.
  • Meta Platforms, Inc. en Google LLC: de bron van elke Instagram-, Facebook- of YouTube-data die je zelf koppelt; hun eigen privacyverklaringen gelden voor hoe zij je account op hun platforms behandelen.

We delen je gegevens met geen enkele andere derde partij, en verkopen ze nooit.

5. YouTube API-diensten en Google-gebruikersdata

De YouTube-functies van het Platform gebruiken YouTube API Services. Door een YouTube-kanaal te koppelen ga je ook akkoord met de Servicevoorwaarden van YouTube. Hoe Google met je gegevens omgaat staat in het Privacybeleid van Google.

  • Nadat je je kanaal via Google-inloggen koppelt, benaderen, verzamelen en bewaren we: de basisgegevens van je kanaal (naam, aantal abonnees, en de videolijst met titels, thumbnails en videoduur) en de statistieken (weergaven, kijktijd, likes, reacties, shares, abonnee-verloop en cijfers per video). Deze gegevens gebruiken we uitsluitend om jouw eigen kanaal-dashboard te tonen aan jou en je beherende agency, ze worden versleuteld opgeslagen binnen je werkruimte, en worden nooit gedeeld met, verkocht of overgedragen aan een andere partij.
  • Ons gebruik van informatie uit Google API's volgt het Google API Services User Data Policy, inclusief de Limited Use-vereisten: Google-gebruikersdata wordt alleen gebruikt voor de hier beschreven dashboardfuncties, nooit voor advertenties, en nooit verkocht.
  • Je kunt de toegang van het Platform tot je Google/YouTube-gegevens op elk moment intrekken via Instellingen → Koppelingen → Loskoppelen in het dashboard, of via je Google-beveiligingsinstellingen.
  • Koppel je los in het dashboard, dan worden de opgeslagen YouTube-gegevens van die koppeling direct verwijderd. Trek je de toegang in via Google's beveiligingspagina, dan worden de opgeslagen YouTube-gegevens binnen 30 dagen na intrekking verwijderd.

6. Hoe lang we ze bewaren, en hoe je ze verwijdert

Kort gezegd: jij hebt de controle. Je kunt zelf op elk moment een koppeling loskoppelen, en je kunt volledige accountverwijdering aanvragen. Beide staan stap voor stap uitgelegd op onze pagina over gegevensverwijdering; de samenvatting:

  • Een koppeling loskoppelen (Instellingen → Koppelingen → Loskoppelen) verwijdert de opgeslagen tokens meteen. We bewaren alleen een minimale vermelding dat de koppeling ooit bestond (de naam van het gekoppelde account en de koppel-/loskoppeldatum), zodat je je koppelgeschiedenis kunt zien als je opnieuw koppelt; die vermelding verdwijnt zodra de werkruimte zelf wordt verwijderd.
  • Je account verwijderen haalt je inlog en profiel meteen overal van het Platform weg. Was je het enige lid van een klant-werkruimte, dan wordt die hele werkruimte, inclusief gekoppelde tokens, DM-geschiedenis, advertentiecijfers en AI-gegenereerde content, in dezelfde stap definitief verwijderd, niet bewaard. Heeft je werkruimte andere teamleden of wordt die beheerd door een agency, dan wordt alleen jouw eigen toegang verwijderd; de gedeelde werkruimte en gegevens blijven bestaan voor de rest van het team. Neem rechtstreeks contact op met je agency om ook die gedeelde gegevens te laten verwijderen.
  • Back-ups: zoals de meeste hostingpartijen maken ook onze database- en hostingproviders routinematige beveiligingsback-ups voor noodherstel. Verwijderde gegevens kunnen daar nog kort in blijven staan tot ze automatisch worden opgeruimd; we herstellen of raadplegen back-ups nooit, behalve bij een écht incident.
  • Sommige gegevens (bijvoorbeeld facturatie- of fraudepreventielogs) kunnen kort bewaard blijven waar we daartoe wettelijk verplicht zijn, maar nooit langer dan nodig en nooit inclusief je externe tokens of berichtinhoud.

7. Beveiliging

Tokens van externe koppelingen zijn versleuteld opgeslagen (AES-256-GCM) en worden nergens in de interface getoond, ook niet aan het eigen team van je agency. Elke werkruimte is op databaseniveau geïsoleerd (row-level security), zodat de ene werkruimte nooit bij de gegevens van een andere kan. Tweestapsverificatie is voor elk account beschikbaar. Al het verkeer is versleuteld onderweg (TLS).

8. Jouw rechten

Onder de AVG en vergelijkbare wetgeving kun je inzage, correctie of verwijdering van je persoonsgegevens aanvragen, en bezwaar maken tegen of beperking vragen van bepaalde verwerkingen. Neem contact op via niek@nrlautomations.com om een van deze rechten uit te oefenen; we reageren binnen 30 dagen.

9. Kinderen

Het Platform is een zakelijk hulpmiddel en is niet gericht op, en wordt niet bewust gebruikt door, kinderen jonger dan 16 jaar.

10. Wijzigingen in deze verklaring

We kunnen deze verklaring bijwerken naarmate het Platform zich ontwikkelt. Wezenlijke wijzigingen zijn te zien aan de datum "Laatst bijgewerkt" bovenaan.

11. Contact

NRL Automations, Niek Beerens, niek@nrlautomations.com

← nrlautomations.com
Built by NRL Automations